Overview
- McKesson said it detected the cybersecurity incident on August 25, 2026 and that unauthorized access to certain third‑party applications led to the exfiltration of data tied to a subset of customers in its Oncology & Multispecialty and Medical‑Surgical units.
- Extortion group ShinyHunters posted McKesson on its Tor leak site, claimed roughly 284 million database rows and demanded about $55 million with a reported negotiation deadline of September 1.
- The attackers told journalists they used voice‑phishing to obtain credentials, took over Okta single‑sign‑on accounts, accessed Salesforce and Snowflake, and said they removed about 1 TB of data over four days, though those technical claims have not been independently verified.
- McKesson says the unauthorized access has been disrupted, its services remain available, it will offer credit monitoring to affected individuals, and its investigation is in the early stages with no detailed data types or victim counts yet released.
- Because McKesson ships a large share of medicines and clinical supplies, the breach could expose patients and providers to identity theft, targeted scams, and regulatory scrutiny under health privacy rules, and downstream organizations should watch for follow‑on phishing and official disclosure updates.